PT-2010-4679 · Microsoft · Office Sharepoint Server+3
Published
2010-10-13
·
Updated
2024-10-17
·
CVE-2010-3243
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Explorer version 8
Microsoft Windows SharePoint Services versions 3.0 SP2
Microsoft Office SharePoint Server versions 2007 SP2
Description
The issue allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. This is due to an information disclosure vulnerability in the way HTML is filtered, which could enable cross-site scripting attacks. An attacker who successfully exploits this could execute a cross-site scripting attack on the user, allowing the attacker to execute script in the user's security context against a site using the toStaticHTML API.
Recommendations
For Microsoft Internet Explorer version 8, update to a version that includes the fix for the HTML Sanitization Vulnerability.
For Microsoft Windows SharePoint Services versions 3.0 SP2, apply the necessary security patches to address the information disclosure vulnerability.
For Microsoft Office SharePoint Server versions 2007 SP2, consider disabling the toStaticHTML function as a temporary workaround until a patch is available.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Internet Explorer
Office Sharepoint Server
Sharepoint Server
Windows Sharepoint Services